New startup ideas · AI for people who run the AI themselves · What vibe coders need after the demo
startup concept
Wardkey
Security scanner that finds and fixes exposed keys in vibe-coded apps
Wardkey connects to a Lovable or Bolt-built app, scans for exposed API keys, missing row-level security, open database policies and unauthenticated endpoints, then generates the exact prompt to paste back into the builder to fix each hole.
- Software subscription
- Small business
- Lovable
8
similar startups, last 2 years (38 all-time)
yes
8 matching federal grants and programs
Direction supported by government programs and grants
Test it before you build it
$200 · 4 weeks · 25 prospects
Prove non-technical Lovable builders will pay $29/mo for continuous security scanning after being shown one real hole, for $200 in 4 weeks.
Riskiest assumption · Once shown a real security hole in their live app, a non-technical Lovable builder will pay $29 a month for continuous re-scanning rather than fix the one hole themselves and walk away.
1Focus group: who and where
A solo, non-technical Lovable or Bolt builder whose app just got its first 10 to 100 paying users, holds real customer data, has no engineer on staff, and just saw a viral thread about leaked Supabase keys.
where to find 25 · The official Lovable Discord and the r/lovable subreddit (community); makers who launched a live Lovable app on Product Hunt in the last 60 days and the Lovable project showcase gallery (a directory of shipped apps with real users); the #buildinpublic conversation on X and the reply threads under recent posts about leaked Supabase keys and open row-level security (a channel).
2Sell first, build later
A continuous security watch for your live Lovable app: we scan on every deploy for exposed keys, open database policies and unauthenticated endpoints, rank the holes in plain English, and hand you one-click fix prompts. First cohort onboarded within 30 days.
the ask · $29 per month per app, or $19 per month locked for a year with a $49 founding pre-order.
a real yes · A real yes is a $49 founding deposit charged to a card, or a prepaid first month. Compliments in Discord, 'I would totally use this', and free-scan requests that never convert do not count.
3Small experiments
The first one attacks the riskiest assumption; each ends with a number that says whether to run the next.
1. Concierge scan to founding deposit
$60 · 14 days
Recruit 25 builders and have them paste their app URL and repo link. The founder manually inspects each for exposed keys, missing row-level security, open database policies and unauthenticated endpoints, then returns a ranked plain-English report revealing the top hole plus the exact fix prompt to paste into Lovable. Close each report by offering the $49 founding pre-order for continuous re-scanning.
keep going if · 8 of 25 builders who receive a report put down a $49 founding deposit.
2. DM the recently burned
$0 · 10 days
Send 40 direct messages in the Lovable Discord and r/lovable to builders who posted about leaked keys, auth questions, or their first paying users, offering a free scan this week. One founder runs it from a personal account, no automation.
keep going if · 12 of 40 DMs turn into a booked free scan.
3. Priced landing smoke test
$140 · 14 days
Stand up a one-page site describing Wardkey with a 'Reserve my scan' button that takes a card for the $49 founding price. Drive roughly 300 visits with organic posts in r/lovable, the Discord and a Product Hunt teaser.
keep going if · 15 of 300 visitors start founding checkout.
4Collect a deposit up front
Tesla took $1,000 refundable reservations for the Model 3 and $100 for the Cybertruck before building either: the deposit is the measurement, not the revenue.
$49
per prospect, refundable
how · A refundable founding pre-order taken by card through a checkout on the landing page. This buyer is self-serve at a low price with no sales call, so a card-taking pre-order mirrors the real purchase and is the honest measure of intent. set up: Stripe Checkout ↗
what it reserves · A first-cohort scan slot and the $19 per month founding price locked for 12 months instead of $29.
refund · Fully refundable for 30 days, and automatically refunded if your first scan turns up no real security hole.
target · 8 founding deposits from 25 builders scanned within 30 days.
Go: build it if
8 or more of 25 scanned builders convert to a $49 founding deposit within 30 days (32% or more), and the scan surfaces a real hole in at least half the apps.
Kill: stop if
Fewer than 3 of 25 convert (under 12%), or free scans get requested but almost none turn into a deposit.
5 Scripts to run itoutreach message, landing copy, deposit terms · click to open
outreach message
You just got your first paying users on Lovable, and you saw the thread about leaked Supabase keys. I built a scanner that checks your live app for exposed keys, open database policies and unauthenticated endpoints, then hands you the exact prompt to paste back into Lovable to close each hole. I will scan your app free this week and show you what is open, no signup. Worth a 20-minute call so I can walk you through the report?
landing page
Find the security holes in your Lovable app before anyone else does $49 locks founding access: continuous re-scanning on every deploy at $19/mo for a year, not $29. Paste your app URL and reserve your first-cohort scan slot.
deposit terms
Your $49 reserves a founding membership: continuous re-scanning locked at $19 a month for 12 months and a priority slot in the first scan cohort. It is fully refundable for 30 days, and refunded automatically if your first scan finds no real security hole. We open cohort access within 30 days.
Would you run this test?
One tap. The yes-share feeds the Demand pillar of this idea's score; nobody sees who answered.
Budgets are out-of-pocket estimates for a team of one to three, US market. Size the deposit to the deal, and check the terms before taking money in a regulated line.
Scorecard
Ranked against every idea in the catalog: trend, demand and 100x potential from the corpus, competition relative to the other ideas. A generated concept has no judges or swipes yet, so its pillars use the data signals only.
55
Idea Score, 0-100 · raw 33.9 x 1.61
Active
competition: more crowded than 73% of ideas · headwind x0.64
+3.7
government priorities, secondary (25 matching grants)
Trend
23
Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.
- Entrants 2025-26 vs 2023-24 (similar companies)18
- Rounds announced 2025+ in the sector0
- Sector direction (live batch)50
Demand
65
Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.
- YC asks for it (current RFS: idea / sector)30
- Someone already pays (similar companies, recent / all-time)100
100x potential
73
Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.
- Neighbours still alive73
Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 382 ideas in the catalog; the terms matched were security, scanner, finds, fixes, exposed, keys, vibe-coded, apps.
The concept in full
- What
- Wardkey connects to a Lovable or Bolt-built app, scans for exposed API keys, missing row-level security, open database policies and unauthenticated endpoints, then generates the exact prompt to paste back into the builder to fix each hole. In the first hour a solo builder pastes their app URL and repo link, gets a ranked list of holes in plain English, and closes the top three with one-click fix prompts. It re-scans on every deploy and emails when a new hole appears.
- Grounded in (2025-2026 signals)
- Lovable reached '$200 million ARR in November 2025 and about $500 million by June 2026 with 146 staff; 80% of the people building on it are not developers'; Lovable raised another $400M on 2026-08-12; 'vibe coding' was Collins' Word of the Year on November 6, 2025; YC's Fall 2026 RFS includes 'A Cloud for Small Software'.
- What it rides
- Lovable: $500 million ARR, 80% non-technical builders. Rides it directly: 80% of half a billion dollars of build activity ships without anyone who can read a security diff, and the resulting apps are the install base.
- Why now
- 80% of Lovable's builders are non-technical and the platform hit roughly $500 million ARR by June 2026, so hundreds of thousands of live apps with real user data have no one on staff who can audit an auth rule; the audience only reached this size in the last twelve months.
- Wedge: first customer and entry point
- Lovable builders who just got their first paying users and saw a viral post about leaked Supabase keys; a free scan with one revealed hole converts to $29 a month for continuous re-scanning, sold self-serve with no sales call.
- Closest real companies, as the generator saw them
- Vybe (yc X25) builds secure internal apps from scratch; Wardkey secures the app the user already built on someone else's tool and stays as a monitor. Tinfoil (yc X25) does encrypted AI inference, a different layer entirely.
- Main risk
- Lovable ships a built-in security scan tab and the standalone tool becomes a feature.
Similar startups in the directory
Companies whose pitch matches most of the concept's terms (security, scanner, finds, fixes, exposed, keys, vibe-coded, apps).
Secure internal apps. Built by AI in seconds. Powered by your data.
Autonomous offensive security agents. The best defense is offense
AI mobile app that helps factory technicians fix broken machines
Frontier AI Defenses for Social Engineering Attacks
Security builds trust. Strengthen both, all on one platform.
Continuous AI pentesting that finds and fixes vulnerabilities
UzimaNexus | Transforming Healthcare with AI & Blockchain
The AI Security Engineer to Find and Fix Vulnerabilities
Automatically find and fix your software vulnerabilities
Application security on auto-pilot: automatically find and fix security vulnerabilities before production.
We are building the home of interactive entertainment for 5 billion soccer fans.
Agents that handle security work
Public money in this direction
US federal grants and open opportunities matched to the concept's terms.
NIH / NHLBI · STTR phase I · $606K
National Science Foundation · I-Corps · $50K
National Science Foundation · SBIR Phase II · $1M
NIH / NIDDK · STTR phase I · $350K
NIH / NIA · SBIR phase II · $500K
NIH / NCI · SBIR phase II · $2M
NIH / NEI · SBIR phase II · $566K
NIH / NHGRI · STTR phase I · $395K
Other concepts in this collection
- SkillproofRegression testing for the Agent Skills you actually depend on
- ProvenaryScan third-party skills and MCP servers before you let them touch your data
- LedgerkitVersioned skill packs that make a solo CPA's assistant work like a tax practice
- VendfoldLicensing, signing and auto-update infrastructure for people who sell Agent Skills
- PackroomOne shared skill library for a team where everyone runs their own agent
- TokentabPer-skill cost, routing and drift telemetry for the person who runs AI all day
- ThreadkeepA memory vault you own that every assistant you run can read
- RelayfileHand a running task from Claude Code to Codex without losing state
- MeterhouseOne budget, meter and kill switch for every agent you run
- AttestlyAudit trail and approval inbox for the agents you run at work
- SkillvaneVersion control and regression tests for the skills your agents load
- CrewlineA shared board where each teammate's agents pick up each other's work
- StillupUptime and error monitoring that answers in fix prompts, not stack traces
- CopystoneAutomatic backups and one-click restore for apps built without engineers
- GroundskeepMonthly maintenance for shipped vibe-coded apps, applied as reviewable patches
- TillhousePayments, sales tax and refunds as one drop-in for non-developer founders
- SpendgateMeter, cap and route the AI spend inside apps vibe coders shipped
- DryloopRehearsal mode for the automations a small business owner builds alone
- MeterlyOne metered key with spend caps for every AI step you run
- FlowmedicWatches your automations, explains failures in plain English, proposes the fix
- ScrubdeckA data-cleaning step any workflow can call, with rules the owner keeps
- OpshandTurns your written SOPs into versioned Agent Skills with tests included
- CrewtraceShared visibility when five people at one business each run their own automations
- VeraciteCitation verification and AI work records for solo attorneys who draft with Claude
- TickstoneTurns a solo CPA's AI sessions into reviewable workpapers with tickmarks and source trails
- ChartproofA verification layer for physicians who use AI on clinical notes under their own license
- CoverlensPolicy-form verification for independent insurance agents who quote with AI
- MethodkitSolo consultants package their methodology as versioned Agent Skills they own and resell
- AttestrailTamper-evident logs of every AI action, built for licensed professionals' liability files
- ScrublineLocal redaction proxy that makes your personal AI accounts safe for work data
- StipendlyTurn personal Claude Max and ChatGPT Pro seats into managed employer stipends
- TollgateA policy gateway between your assistant and every MCP server it touches
- SkillvetScan, pin and approve Agent Skills before they touch company data
- DaylightSelf-serve shadow AI registry and policy for companies with no security team
- LedgerlineRightsizing dashboard for everyone paying for AI out of their own pocket
- SwitchyardOne metered endpoint with routing, fallback and per-person caps for tiny teams
- HearthmeterUsage budgets and one bill for the household that shares AI plans
- SeatcaseMeasures who on your team earns a Max seat and who wastes one
- TokencairnProfiler that shows what each installed skill and MCP server really costs
- FusegateBudget caps, fallback and kill switches for automations you run yourself
- SkillbenchRegression testing for Agent Skills before every model and skill update
- CitelockVerifies every citation in AI-drafted work before a licensed professional signs it
- MiddlegateA local gateway where you set the rules for what your MCP servers can do
- DriftwatchCatches output drift in the automations small operators wired themselves
- ShipcheckPre-launch review gates non-technical builders run on their own vibe-coded apps
- TracelineA claim-level provenance trail for every number in an AI-assisted report
- DrillyardScored practice repos where you learn to drive coding agents well
- PassrateA proctored AI operation exam scored from your real agent transcripts
- PatchcraftDebugging drills that teach non-technical builders to maintain what they vibe coded
- SkillsmithA workshop for writing, testing and versioning Agent Skills that actually hold up
- TickmarkSynthetic client caseloads where CPAs drill AI-assisted work before trying it on real clients
- PostgameAn MCP server that scores your own agent sessions and drills your weakest habits
- CitegridEvery number in your published research links to a source snapshot you verified
- MnemosYour research corpus as a private MCP server every assistant can query
- MeterlineModel routing and cost accounting for one person's AI research pipeline
- SkillcaskVersion, test, and sell your expertise as licensed Agent Skills
- StackfeedA personal data pipeline that repairs itself when sources change
- ClaimboardA shared evidence ledger for small teams where everyone runs their own agent
Fictional concept generated 2026-08-26 by claude-fable-5 from the collection's brief and MarkosWeb data. Treat it as a research prompt, not a plan.